[ad_1]
Further details are being revealed following a July 2 attack on cross-chain bridging platform Poly Network, where a hacker could issue billions of tokens out of thin air for profit.
In a July 2 tweet, Poly Network confirmed that it had become the latest victim of a decentralized finance (DeFi) exploit after attackers successfully manipulated a smart contract function on the cross-chain bridge protocol. , adding that it would temporarily suspend services.
In the latest update, the team revealed that the exploit affected 57 crypto assets across 10 blockchains, including Ethereum, BNB Chain, Polygon, Avalanche, Heco, OKX, and Metis.
It did not specify how much was stolen in the attack, but PeckShield previously reported that the exploiter transferred at least $5 million in crypto.
Tokens transferred out of Poly Network. Source: Twitter/PeckShield
We have already initiated communication with centralized exchanges and law enforcement and have requested their assistance, the team said in a July 3 update.
He also advised project teams and token holders to withdraw liquidity and unlock their liquidity provider tokens.
34 billion Poly Network hacking failures
DeFi security analyst Arhat said the exploit resulted from a smart contract vulnerability that allowed the hacker to create a malicious parameter containing a fake validator signature and block header.
This was accepted by the smart contract, allowing the hacker to bypass the verification process and allowing them to issue tokens from the Poly Networks Ethereum pool to their own address on other chains, such as Metis, BNB Chain, and Polygon.
The process was repeated for other chains allowing the pool of tokens to accumulate.
At one point, the hackers’ wallet held around $42 billion worth of tokens, but they were only able to convert and steal a fraction of it, the analyst said.
This way, the hacker was able to mint billions of tokens on various blockchains that did not exist before and transfer them to their own wallet addresses.
Blockchain security solution provider Dedaub dubbed Poly Network’s latest exploit the 34 billion Poly Network hack.
Getting to the bottom of the Poly Network “34 billion” hack with a technical post-mortem.
TL; DR
The Poly network had a simple 3 of 4 multisig arrangement over 2 years!
Looking at the final event, we found that the private keys of the marked addresses were compromised. pic.twitter.com/Y0eMJXcYso
Dedaub (@dedaub) July 2, 2023
Dedaub noted weaknesses in multisig protocols, stating that he had a simple 3 out of 4 multisignature arrangement over two years, adding:
Looking at the final event, we found that the private keys of the marked addresses were compromised.
Dedaub explained that the attack was not complex, as no logic bugs were exploited. He added that Poly Network took seven hours to respond, which cost the platform $5.5 million in stolen crypto. Fortunately, a lack of liquidity in many tokens prevented further losses.
Related: Over $204M Lost to DeFi Hacks and Scams in Q2
Following the attack, Binance CEO Changpeng Zhao reassured customers, saying it does not affect Binance users. We do not support repositories from this network.
Poly Network was again rekt; allegedly due to compromised shortcut keys.
This will continue until our industry changes its approach to security.
Smart contract audits only scratch the surface.
ps The Poly network has NOTHING to do with Polygon. https://t.co/n1qI48b4Kb
Mudit Gupta (@Mudit__Gupta) July 2, 2023
Cointelegraph contacted Poly Network for further details but received no response per post.
In August 2021, the Poly network was attacked in one of the biggest exploits in the industry. The hackers were later revealed to be linked to the North Korean hacking collective, the Lazarus Group grabbed more than $600 million.
Magazine:Tornado Cash 2.0: The Race to Build Safe and Legal Coin Mixers
|
Sources 2/ https://cointelegraph.com/news/poly-network-users-withdraw-bridge-exploit-affects-57-crypto The mention sources can contact us to remove/changing this article |
[ad_2]